LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-12-2004, 12:14 PM   #1
weezel
LQ Newbie
 
Registered: Jun 2004
Location: Guildford, Surrey, UK
Distribution: Redhat 9.0
Posts: 10

Rep: Reputation: 0
FTP Security on Redhat 9.0


Hi there,

I currently run vsftpd on redhat 9.0

My question is, when i log in via ftp, using an account that isnt an owner on the server, in the remote dir box, it lists, "/home/weezel" it also allows to to go from that, to / something that isnt exactly secure!

Any ideas how i fix ???

thankyou
 
Old 06-12-2004, 02:17 PM   #2
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
From "man vsftpd.conf":
Quote:
chroot_local_user
If set to YES, local users will be placed in a chroot() jail in their home directory after login. Warning: This option has security implications, especially if the users have upload permission, or shell access. Only enable if you know what you are doing. Note that these security implications are not vsftpd specific. They apply to all FTP daemons which offer to put local users in chroot() jails.

Default: NO
 
Old 06-12-2004, 07:53 PM   #3
weezel
LQ Newbie
 
Registered: Jun 2004
Location: Guildford, Surrey, UK
Distribution: Redhat 9.0
Posts: 10

Original Poster
Rep: Reputation: 0
Brilliant, Thankyou

Okay, so i did that and it worked, but, it places the user in / with nothing visible in that dir.

where/what is that dir on the server? i tried adding files to the users home dir, but they didnt show up, and they were the owner.

?? im confused!


EDIT>>> Its working now, going to play with it a bit

probably my last question... How do you bind vsftpd to another port, other than 21? i have 22 through 28 open on my router, forwarded to that pc, and would like to use one of those

Last edited by weezel; 06-12-2004 at 08:01 PM.
 
Old 06-13-2004, 11:11 AM   #4
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
From "man vsftpd.conf":
Quote:
listen_port
If vsftpd is in standalone mode, this is the port it will listen on for incoming FTP connections.

Default: 21
Take a look at the man pages first - it will save you a lot of time.
 
Old 06-13-2004, 11:16 AM   #5
weezel
LQ Newbie
 
Registered: Jun 2004
Location: Guildford, Surrey, UK
Distribution: Redhat 9.0
Posts: 10

Original Poster
Rep: Reputation: 0
u rock man

ty ty
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ftp security msamuels Linux - General 3 05-31-2005 11:58 PM
ftp security spate Linux - Software 1 01-19-2003 06:04 PM
FTP Security?? Milkman00 Linux - Software 3 08-10-2002 11:10 PM
FTP security ! chuck77 Linux - General 4 03-05-2002 12:09 AM
FTP security vcheah Linux - Security 6 01-06-2002 04:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration